Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2021-05-07 CVE-2021-21984 Missing Authorization vulnerability in VMWare Vrealize Business for Cloud 7.0
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point.
network
low complexity
vmware CWE-862
critical
9.8
2021-04-19 CVE-2021-21981 Improper Privilege Management vulnerability in VMWare Nsx-T Data Center 3.1.1
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment.
local
low complexity
vmware CWE-269
7.8
2021-04-01 CVE-2021-21982 Improper Authentication vulnerability in VMWare Carbon Black Cloud Workload 1.0/1.0.1
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token.
network
low complexity
vmware CWE-287
critical
9.1
2021-03-31 CVE-2021-21983 Unspecified vulnerability in VMWare products
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
network
low complexity
vmware
6.5
2021-03-31 CVE-2021-21975 Server-Side Request Forgery (SSRF) vulnerability in VMWare products
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
network
low complexity
vmware CWE-918
7.5
2021-03-15 CVE-2021-26987 Element Plug-in for vCenter Server incorporates SpringBoot Framework.
network
low complexity
vmware netapp
critical
9.8
2021-03-03 CVE-2021-21978 Missing Authorization vulnerability in VMWare View Planner 4.6
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability.
network
low complexity
vmware CWE-862
critical
9.8
2021-03-01 CVE-2021-22114 Path Traversal vulnerability in VMWare Spring Integration ZIP
Addresses partial fix in CVE-2018-1263.
network
low complexity
vmware CWE-22
5.3
2021-02-24 CVE-2021-21974 Out-of-bounds Write vulnerability in VMWare Cloud Foundation and Esxi
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability.
low complexity
vmware CWE-787
8.8
2021-02-24 CVE-2021-21973 Server-Side Request Forgery (SSRF) vulnerability in VMWare Cloud Foundation and Vcenter Server
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin.
network
low complexity
vmware CWE-918
5.3